Question
Automatically block IP
Each day, I see numerous (as in 1000' s) of invalid login attempts on my network through our RemotApp web interface. I see this in the security log of the target machine. There are usually a dozen or so IP addresses that these come from each day. I have been noting the IP that the requests are coming from and then I add to policy rule which blocks incoming and outgoing traffic to that IP. This works but requires manual review, and only occurs after the attempts have been running for a while (I have an alert set up on the event log for when an account is locked out from too many invalid login attempts). I know this is not a good way to do this but don' t know how to do it any other way. Any suggestions for how to automate this on my FortiGate or other approaches that I should be considering? Thanks.
